Financial services now have the most expensive breaches in Australia: what the 2026 numbers mean

blank

Financial services now have the most expensive breaches in Australia: what the 2026 numbers mean

blank

Every year, IBM’s Cost of a Data Breach Report gives Australian businesses a clear benchmark for what a security incident costs. It’s one of the few studies of its kind that lets organisations compare their own exposure against a large, consistent global dataset year after year.

The 2026 edition, published on 31 July 2026, examined breaches experienced by 602 organisations globally between March 2025 and February 2026. As in previous years, the report breaks these findings down by industry and region, giving a picture of how different sectors are faring against the same threats. Buried in the Australian results are several findings financial services leaders can’t afford to overlook.

The numbers

The average cost of a data breach in Australia has risen toAUD $4.22 million, up 38 per cent since 2019.

Financial services recorded the highest average breach cost of any sector in the country, at AUD $6.31 million per incident (IBM, 2026). It is now the most expensive sector in Australia to experience a breach, ahead of every other industry IBM measured this year.

It helps to understand what that figure represents, because it is easy to read it as a single dramatic event and move on, however, it isn’t one. It is an average, built up from incident response, forensic investigation, regulatory notification, lost business and the time it takes a Financial Services firm to identify and contain an issue once it has started.

For a sector that holds sensitive client information and moves money for a living, each of those components tends to run longer and cost more, and the total adds up quickly.

A trend, not a spike

The cost figure lines up with what’s happening on the reporting side too. The Office of the Australian Information Commissioner received1,205 data breach notifications in 2025, the highest number since the Notifiable Data Breaches scheme began in 2018, and an 8 per cent increase on the 1,112 notifications recorded in 2024 (OAIC, 2026). A consistent picture can be seen when you read the two data points together.

Breaches are being reported more often across the board, and when they land in financial services, they cost more to resolve than anywhere else.

None of this means Financial Services firms are doing something wrong, it reflects the nature of the work being completed. Businesses in this sector hold information and manage transactions, so a breach is not just costly to put right, it also comes with strict reporting obligations to regulators.

blank

Where the value sits

What the figure highlights is the value of preparation before an incident, not after one. The businesses that survive a breach with less damage rarely do so by chance. They usually have a plan that was written and tested well before it was needed, so the first hour of an incident is spent executing it rather than working out where to start.”

Picture two businesses hit by a similar incident on the same day. One already knows who gets notified, in what order, and what the client message says, before anyone’s written a word of it. The other is figuring all of that out for the first time, with the clock already running. That gap, in cost and in client trust, is most of what this report is measuring.

Closing that gap doesn’t call for a finished plan overnight, and it doesn’t need to be perfect on the first attempt, it just needs to exist before it’s tested for real.

How can we help you?

Join us for a Cyber Webinar Series where we unpack practically how you can learn and discover how to not only protect your environment, but who has access to it and what information they have access to. 
 
More information is found here: 
https://danet.com.au/webinar-series-three-cyber-security-questions-every-business-owner-has-to-answer/

If you’d like to talk through what this means for your business, contact us.

danet.com.au

Sources

OAIC, Data breach notifications increase to all-time high in 2025, new NDB stats show (published 6 July 2026): https://www.oaic.gov.au/news/media-centre/data-breach-notifications-increase-to-all-time-high-in-2025,-new-ndb-stats-show

IBM, Cost of a Data Breach Report 2026: https://www.ibm.com/reports/data-breach

AI & Actionable Insights in 2026 Guide for AFSL Holders

AI & Actionable Insights in 2026 Guide for AFSL Holders

blank

Download the guide

AI & Actionable Insights in 2026

A 5 minute read for Australian financial services executives. Covers Danet’s survey of financial services firms, the account type rule, four risk areas, and three executive moves for the next month.

Your team is using artificial intelligence today, in tools you may or may not have approved. Inside a regulated financial services firm, that creates new questions about client privacy, supplier risk, and the version of every Microsoft, Google or OpenAI product your staff are actually logged into.

Written for executives, read in five minutes, designed to be forwarded to your information technology partner or compliance lead.

Whats Inside

  • Headline findings from the Danet Artificial Intelligence Experience & Insights Survey
  • The 5 AI tools your team is most likely already using
  • The account type difference: personal, enterprise and tenant bound Microsoft 365 Copilot Chat
  • The 4 risk areas specific to a regulated financial services firm
  • The 3 executive moves for the next 30 days

Cyber & RG104 Guide for AFSL Holders

Cyber & RG104 Guide for AFSL Holders

blank

Download the guide

Meeting Your RG 104 Obligations.

A 5 minute read for Australian financial services executives. Covers the four RG 104 obligation areas, the five foundational controls, a 90 day plan, and nine questions for your IT partner.

Written for executives, read in five minutes, designed to be forwarded to your information technology partner or compliance lead.

Whats Inside

  • The 4 RG 104 obligation areas and the section 912A duty behind them
  • The 5 foundational cyber controls mapped to RG 104.100’s 10 review criteria
  • 30 / 30 / 30 day plan: assess, remediate and evidence
  • The 9 questions to put to your information technology partner
  • Recent ASIC enforcement: RI Advice, FIIG Securities, ASIC supervisory posture

How AI hallucinations could land for AFSL holders

blank

How AI hallucinations could land for AFSL holders

blank

With 90% of industry leaders believing AI will improve service and efficiency in their firms,attention is now turning to how this technology is integrated into everyday workflows, and how its behaviour shapes outcomes.

A specific pattern emerging is AI hallucinations, where AI recognises objects or patterns that don’t exist or that humans are unable to see.

The problem with this? Inaccurate, invented responses, with no supporting evidence or insight, and errors hard to detect due to the confidence AI responds with.

AI is going to be part of every Australian financial services organisation, the right approach is choosing the version that protects your client data.

AI hallucinations in the real world

In 2023, AI hallucinations appeared in the legal case of Mata v. Avianca. An attorney was representing an injury claim for a client, using ChatGPT this produced references that did not exist in the legal research.

It also falsely claimed the references came from a reputable legal database, revealing how far AI can go in producing inaccurate outputs.

The knowledge base AI utilises continued to be undermined. From 2023-2025, cases like these kept emerging, with judges worldwide issuing hundreds of filings, 90% of them in 2025 alone.

For AFSL holders, in a Statement of Advice, this can land as AI-generated errors appearing as verified content, which risks consumers being misled by incorrect facts and insights.

Why this matters to AFSL holders

AFSL holders need to ensure that consumers aren’t unethically treated through vulnerability exploitation and potential AI bias.

The accuracy of insights and facts produced to consumers must also oblige ensuring AI information isn’t misleading, unexplained, or inaccurate.

Under directors’ duties, responsibilities must be undertaken carefully and diligently when considering reliance on information from AI and the risk that it holds.

Without upholding these obligations, an uncaught hallucination in a Statement of Advice, client email or compliance file note becomes an AFCA complaint, a breach report, and a remediation bill the licensee carries.

A confident approach to AI

For AFSL holders to ensure they can meet these obligations, Microsoft 365, specifically Microsoft Copilot, is a safe way to implement AI. Designed specifically for enterprise, Copilot operates within an organisation’s tenant.

The benefits of Microsoft 365 involve:

Data protection and strict permissions: Adheres to an organisation’s existing data permissions and information, no exposure of organisational data to train the public AI model.

Automated compliance:Finds regulatory changes and prepares for audits, allowing adherence to compliance standards.

Microsoft purview:Prevents unauthorised data sharing, monitors AI prompts, and classifies sensitive data.

Many organisations already have these capabilities within their environments, they just haven’t been optimised yet. For financial services organisations, accuracy can be enhanced through role-specific AI agents, allowing for automated data reconciliation.

Reliable and permitted outputs can also be achieved through a strong SharePoint architecture and governed data access, allowing Copilot to search through categories.

The next 3 steps

There are a series of steps AFSL holders can take to ensure continued confidence within their environments.

  1. Embed Copilot through existing applications and actively update databases
  2. Ensure data governance through implementing restrictions and Microsoft Purview
  3. Updating policies around AI that mandate human review

These measures ensure Copilot can function optimally in your environment while maintaining data and access governance supported by updated AI policies.

Why Danet

With AI being part of how financial services will operate in 2026 and beyond, hallucinations will progressively surface.

Those who move first with the right version of AI will benefit from the productivity without the privacy risk.

Danet works with organisations to align Microsoft 365 and Copilot to their environments to ensure confidence and compliance with the use of AI, through designing and continuing to update the structures of databases and workflows.

These themes are further explored in Danet’s AI Guide for AFSL Leaders, determining how AI capabilities can be implemented into Microsoft 365 environments and how governance oversight shapes this.

AI is already in your environment: understanding how different tools interact with your data

AI in your environment

AI is already in your environment: understanding how different tools interact with your data

blank

This is changing how every business operates and how day to day processes are completed. Confidential information, client accounts and internal documents are most likely being passed through or viewed by AI multiples time a day. In many businesses, AI is in contact with this information without clear oversight on how these systems are being used or where organisational data is being retained.

Do know how AI is being used in your workplace? Have you tested access to internal documentation?

The type of AI platform makes a difference

Copilot operates within Microsoft 365 through Entra ID and existing Microsoft permissions. The information it surfaces reflects the same access structures already governing collaboration inside SharePoint, Outlook and Teams. This keeps AI activity connected to the identity and access controls already established across the environment.

External AI platforms operate differently. ChatGPT, Claude and Gemini are commonly accessed through browser sessions or personal accounts operating outside Microsoft 365 governance oversight. Staff may paste client information or internal notes into these tools during routine work. Once information enters those platforms, the organisation may have limited oversight around retention model usage or where that information is processed.

AI capability is also becoming embedded into software already used across financial services environments. Meeting intelligence tools can generate summaries from conversations while CRM platforms surface AI-driven prompts during workflow activity. Research platforms now return AI-generated responses inside the application itself.

Over time, organisational data begins moving through multiple AI environments operating under different data handling conditions.

Identity and access can change AI behaviour

Identity governance plays a larger role in how organisational data is surfaced across the organisation.

Microsoft 365, Entra ID defines the identity boundary through which Copilot interacts with information. Existing permissions determine which content available through your Microsoft Modern Workplace can appear through AI-driven search and summarisation. Records and internal knowledge continuously move between collaboration spaces during normal work. AI systems now interact with that same information structure, which places greater importance on maintaining access aligned to operational responsibility.

As AI capability expands identity governance further shapes how confidently organisations can maintain control over the information AI systems can access throughout the environment.

blank
blank

AI increases visibility into operational maturity

AI systems are interacting broadly with organisational data, this means the maturity of the environment becomes easier to observe.

Information ownership remains clearer when access responsibilities continue reflecting how teams currently operate across the organisation. Permissions also remain easier to govern when environments are reviewed as collaboration patterns evolve over time.

This is shifting AI governance discussions toward the condition of the environment itself. Organisations with clear ownership and structured access practices are often better positioned to introduce AI capability into connected workflow activity.

AI capability reflects the maturity of the environment it operates within.

Financial services environments carry additional governance expectations

Questions around governance oversight are important in financial services firms as AI systems begin interacting with client information.

For many AFSL holders here are some practical questions you should be asking.

  • Which AI platforms are staff already using during client-related work?
  • Are staff entering regulated information into personal AI accounts?
  • Which AI tools retain prompts or uploaded material outside the organisation?
  • Does the business have oversight around where AI-generated outputs are stored or shared?
blank

Why Danet

Danet works with organisations to structure Microsoft 365 environments where governance oversight remains aligned with the way AI capability evolves across connected platforms and the information within them.

Within financial services environments, this includes maintaining oversight around how AI systems interact with information moving through regulated workflow activity.

For financial services organisations, these themes are explored further in Danet’s AI Guide for AFSL Leaders, which examines how governance oversight shapes the way AI capability is introduced across connected Microsoft 365 environments.

Stellan Capital & Danet Technology Case Study

blank

Stellan Capital &
Danet Technology Case Study

blank

Stellan Capital is a private wealth firm operating in the ultra-high-net-worth and multi-family office segment. Founded by executives from global investment banks including Goldman Sachs, Deutsche Bank, and Morgan Stanley, the firm provides sophisticated, global, multi-currency portfolio management services.

As Founding Partner, David Leon puts it, “we aren’t a bank and so our capital isn’t dollars, it’s our credibility. A client data privacy leak is the single greatest existential threat to our firm.”

Danet was engaged early as a strategic partner, not just a vendor. The relationship is deeply collaborative, with founder-to-founder alignment on values, rigour, and client protection.

Implementation of Danet Technology services

Danet has supported Stellan through multiple cybersecurity maturity phases, from foundational setup to an advanced security uplift. Key initiatives have included:

  • Secured device management and firewall control
  • Access governance and endpoint security
  • Cybersecurity audits and ongoing control enhancements
  • Deployment of phishing simulations and staff training
  • Custom escalation workflows for internal requests
  • Early adoption guidance for AI platforms with cybersecurity overlays

Notably, Danet developed a phishing resilience program tailored to Stellan’s needs, sending custom simulations to test team awareness, track engagement, and address behavioural risks.

“The founder-to-founder, bespoke approach was the game-changer for us, especially as we grew. Danet never tried to squeeze us
into an off-the-shelf model.”
blank
David Leon

Business Impact

Stellan has scaled from five to over twenty employees, with further growth underway. Danet’s infrastructure and oversight have enabled safe growth with zero incidents.

The benefits go beyond operations:

  • Confidence in third-party audits (e.g., RG104 and Microsoft best practice)
  • Trust from UHNW clients, even amid broader industry breach news
  • Access to transparent reporting and evolving security innovations
Amanda Garmston, Chief Operating Officer, “A great cyber tech stack is like the perfect pair of shoes: after day one, you don’t even
notice you’re wearing them. Danet has made our
tech experience that smooth.”
blank
Amanda Garmston

What stood out most for Stellan Capital was Danet’s ability to matchtechnical depth withstrategic responsiveness.

Unlike firms that apply a one-size-fits-all model, Danet delivered a bespoke approach tailored to Stellan’s specific risk profile,
regulatory sensitivity, and growth ambitions.
blank
David Leon
Founding Partner, Stellan Capital.

Knightswood House Private Wealth & Danet Technology Case Study

blank

Knightswood House
Private Wealth &
Danet Technology Case Study

blank

Knightswood House is a boutique financial advice firm delivering holistic wealthadvice to a carefully curated group of private clients. Founded on the principle of outcome-based financial guidance, Knightswood helps clients align personal priorities with financial decision-making, with an emphasis on quality of life and financial well-being over just the accumulation of wealth. 

As a highly digital-first firm, technology plays a central role in client service delivery, document access, and regulatory compliance. When legacy systems became unworkable, founder David Hazlewood turned to Danet, not just as an IT provider, but as a strategic partner.

“Dan took me through a process not unlike what I use with my own clients, understanding the goal, identifying the gaps, outlining a plan, and managing the risk.”
— David Hazlewood

Implementation of Danet Technology services

Danet overhauled Knightswood’s technology landscape by migrating systems into the Microsoft Cloud, retiring a bespoke, unsupported system that was no longer fit for purpose.

The transformation included:

  • Microsoft 365 deployment with secure cloud storage
  • Admin privilege redesign (segregated access to limit breach exposure)
  • Cyber hygiene controls including geographic access restrictions
  • Ongoing cyber awareness and phishing simulations

Danet also conducts regular phishing tests and simulated breach drills to test team awareness. This ensures compliance with evolving cyber audit expectations and instills confidence across the firm.

Hazlewood credits Danet’s team for their responsiveness and background protection. “I don’t really hear from them day-to-day,”
he says, “and that’s a good thing, because it just works.
But when we need them, they’re there.”
blank

Business Impact

The result of this transformation has been seamless operations, even as the firm operates flexibly across locations and engages offshore resources. Hazlewood notes the tangible security benefits:

  • Systems accessible securely from anywhere
  • Administrative segregation protects against privilege misuse
  • Annual cyber audits now return some of the highest scores in the firm’s network
“We’ve had independent auditors tell us our cybersecurity posture is better than 99% of firms in the network. That gives us peace of mind, and our clients reassurance.”
blank
David Hazlewood

Operationally,it’s also about sustainability and ease of work. Knightswood is not looking to scale at pace, but tomaintain quality, profitability, and lifestyle, and Danet enables that with a reliable, low-friction IT experience.

They’ll look after your IT systems the way you look after your clients.”
blank
David Hazlewood
Founder, Knightswood

Cybersecurity and AFSL compliance and what every financial services leader needs to know

blank

Cybersecurity and
AFSL compliance and
what every financial services leader needs to know

blank

In 2022, ASIC updated its guidance under Regulatory Guide 104 (RG 104), reinforcing the responsibility of Australian Financial Services License (AFSL) holders to maintain adequate technological resources.

For leaders in financial services, this means that cybersecurity is no longer an optional IT issue, it is now central to your compliance obligations, business continuity, and client trust.

But what does RG104 mean?

RG104 makes it really clear to all AFSL holders, they must maintain technology that is both stable and secure, aligned to the nature, scale and complexity of their financial services business. However, RG104 is well beyond the right infrastructure.

As an overview RG104 obligations highlight:

  • Cybersecurity and information security
  • Risk management systems
  • Outsourced IT Oversight
  • Incident Response
  • Employee Training & Supervision

So why is this important?

Over the last 18 months, multiple financial services firms in Australia have faced ASIC enforcement actions, not just because they were breached but because they couldn’t demonstrate adequate cyber risk management before a breach occurred.

In one high profile case in 2023, a boutique Advisory Firm received $1.2million penalty and temporary suspension of license operations due to failure to implement basic cybersecurity safeguards including:

  1. No formal incident response plan
  2. Inadequate endpoint protection
  3. No staff cybersecurity awareness training

What are regulators expecting?

ASIC has repeatedly highlighted the importance of the following requirements:

  1. Cyber risk registers as a part of your business risk
  2. Third party oversight including you working with MSPs and cloud vendors
  3. Business continuity plans and stress testing the plans
  4. User activity monitoring and transparency on privilege access controls
  5. ISO 27001 alignment especially where regulatory scrutiny is higher

Need Help?

If you need help in understanding how this will impact your
financial services business, join our Webinar Event.

Daniel Butt, CEO, Danet will be walking through Fin Services obligations and
the right controls – don't just meet these but exceed them when its Audit time.